In GitOps YAML, use the fleet_maintained_apps key with the app's slug to reference a Fleet-maintained app.
When remediating a CVE, use Fleet's built-in vulnerability detection to identify affected software, then follow the Software section above to deploy a fix — preferring a Fleet-maintained app update where available, otherwise a custom package.
Declarative Device Management (DDM)
When generating or modifying DDM declarations:
Validate declaration types, keys, and values against the Apple DDM reference: